Skip to main content

Quickstart Check Point & Securosys HSM

This page provide an overview of how to integrate Check Point Security Gateway with a Primus HSM or CloudHSM. For full details, please see the linked sections of the installation guide.

  1. Prerequisites:
    • Prepare your Check Point Security Gateway Management Server for HTTPS Inspection, ensure HTTPS Inspection works correctly prior integrating.
    • Obtain a Securosys HSM and configure it or use a preconfigured CloudHSM Partition.
    • Prepare an HSM Client Workstation for managing the cryptographic objects on your HSM.
    • On your Securosys HSM create or use an existing a key pair and a CA certificate for use in HTTPS inspection and note down their labels.
  2. Prepare the PKCS#11 Provider:
    • Install and configure the Primus PKCS#11 Provider on your Check Point Security Gateway.
  3. Configure HTTPS Inspection with Securosys HSMs:
    • Specify the provider parameters for the Check Point HSM configuration
    • Specify your CA cert and "fake" certificate key pair labels.
    • Validate HSM configuration, Check Point provides monitoring capabilities. See Monitoring HTTPS Inspection with HSM in CLI

The HTTPS Inspection CA key and "fake" certificate key pairs are generated and stored within the HSM secure boundary.

HSM Availability

If the HSM Server is not available when you fetch the local policy or install the policy in SmartConsole, the HTTPS Inspection cannot inspect the Outbound HTTPS traffic. As a result, internal computers behind the Security Gateway / Cluster / Security Group / VSX Virtual System cannot access HTTPS web sites.

Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?